CIPP Cheat Sheet 2026

The 30 highest-yield CIPP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

90 questions
150 min time limit
68.00% to pass
  1. Under the Gramm-Leach-Bliley Act (GLBA), what must financial institutions provide to customers at the time of establishing a customer relationship? An initial privacy notice
  2. When must a CCPA-covered business provide a 'Do Not Sell or Share My Personal Information' opt-out link? On its homepage if it sells or shares personal information
  3. Which federal agency has primary enforcement authority over national banks under GLBA's privacy provisions? Office of the Comptroller of the Currency (OCC)
  4. The Fair and Accurate Credit Transactions Act (FACTA) most significantly amended FCRA by establishing: The right to one free credit report per year from each major consumer reporting agency
  5. What right allows California consumers to correct inaccurate personal information held by a business? Right to Correct (added by CPRA)
  6. Which type of entity is directly covered by HIPAA's Privacy Rule? Covered entities (health plans, providers, clearinghouses)
  7. Under US law, what is the primary federal statute governing spam texts sent to mobile phones? Telephone Consumer Protection Act (TCPA)
  8. Which privacy concern arises when employers use social media screening of job applicants? Exposure to legally protected characteristics not visible during the interview process
  9. Under CCPA/CPRA, the right to correct inaccurate personal information must be fulfilled by a business within: 45 days of receiving the request, extendable by another 45 days
  10. Under COPPA, what is the age threshold below which verifiable parental consent is required before collecting personal information? 13
  11. Which US state law was the first comprehensive consumer privacy law passed in the United States? California Consumer Privacy Act (CCPA)
  12. Under the Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act, which requirement applies to all commercial email messages? A clear and conspicuous opt-out mechanism must be included
  13. Which technique renders data outside the scope of HIPAA by replacing direct identifiers with a code, provided a re-identification key is not disclosed? Pseudonymization
  14. Which HIPAA right allows a patient to request that a covered entity not disclose their PHI to their health plan for services paid out-of-pocket? Right to request restrictions on disclosures to health plans
  15. In the context of US employment privacy, which action by an employer is generally permissible without employee consent? Recording calls on company phone systems after providing notice
  16. Which of the following constitutes a 'permissible purpose' for obtaining a consumer report under FCRA? A credit transaction initiated by the consumer
  17. Which type of information was added to many states' breach notification laws following high-profile biometric data breaches? Biometric data (fingerprints, facial recognition)
  18. Under the Privacy Act of 1974, which category of organization is directly regulated? Federal government agencies maintaining systems of records
  19. Which of the following is NOT a permitted use or disclosure of PHI under the HIPAA Privacy Rule without patient authorization? Marketing campaigns selling health products
  20. Under GLBA, which entities qualify as 'financial institutions' subject to its privacy provisions? Businesses significantly engaged in financial activities
  21. The FCRA 'Furnisher Rule' primarily requires entities that report information to consumer reporting agencies to: Maintain reasonable policies to ensure accuracy and integrity of reported information
  22. Under the CAN-SPAM Act, commercial email senders must: Honor opt-out requests within 10 business days and include a physical postal address
  23. Under FERPA, when does a student's (not parent's) right to control education records begin? When the student turns 18 or attends a postsecondary institution
  24. Which concept describes the practice of ensuring that data collected is adequate, relevant, and limited to what is necessary for the specified purpose? Data minimization
  25. Which GLBA exception permits financial institutions to share NPI with unaffiliated third parties without offering consumers an opt-out right? Joint marketing agreement exception
  26. A consumer contacts a credit bureau to dispute an inaccurate item. Under the FCRA, how long does the bureau generally have to investigate the dispute? 30 days
  27. Under the 2023 FTC Safeguards Rule amendment, non-banking financial institutions must notify the FTC of breaches affecting how many customers? 500 or more customers
  28. What is the primary purpose of a 'risk of harm' threshold in breach notification laws? To require notification only when there is meaningful risk of harm to individuals
  29. What is the HIPAA Privacy Rule's general rule on the use of PHI for marketing? PHI cannot be used for marketing without written patient authorization
  30. Which type of employee data is most commonly regulated by state biometric privacy laws like Illinois BIPA? Fingerprint scans used for timekeeping or access control
Turn these facts into recall:
Was this helpful?